[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247974

 
 

909

 
 

194654

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Mozilla Firefox arbitrary code execution Vulnerability

Deprecated
ID: oval:org.mitre.oval:def:6154Date: (C)2009-04-30   (M)2022-10-10
Class: VULNERABILITYFamily: windows




The view-source: URI implementation in Mozilla Firefox before 3.0.9, Thunderbird, and SeaMonkey does not properly implement the Same Origin Policy, which allows remote attackers to (1) bypass crossdomain.xml restrictions and connect to arbitrary web sites via a Flash file; (2) read, create, or modify Local Shared Objects via a Flash file; or (3) bypass unspecified restrictions and render content via vectors involving a jar: URI.

Platform:
Microsoft Windows XP
Microsoft Windows Server 2003
Microsoft Windows Vista
Product:
Mozilla Firefox
Reference:
CVE-2009-1307
CVE    1
CVE-2009-1307
CPE    4
cpe:/o:microsoft:windows_xp::sp3:x86
cpe:/o:microsoft:windows_vista:::x86
cpe:/o:microsoft:windows_xp::sp2:x86
cpe:/o:microsoft:windows_vista::sp1:x86
...

© SecPod Technologies